From 10ae81a18366d1e73a6a25899fd2ddc9f116d7af Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 22:39:30 +0000 Subject: [PATCH 1/3] chore(deps): bump hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml Bumps the actions group with 1 update: [hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml](https://github.com/hyperpolymath/panic-attack). Updates `hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml` from 5e7575340961a21098d8d9600461038897016a4d to acdb9821a67fe0a275b39f1b388be364df7fbd4a - [Release notes](https://github.com/hyperpolymath/panic-attack/releases) - [Changelog](https://github.com/hyperpolymath/panic-attack/blob/main/CHANGELOG.adoc) - [Commits](https://github.com/hyperpolymath/panic-attack/compare/5e7575340961a21098d8d9600461038897016a4d...acdb9821a67fe0a275b39f1b388be364df7fbd4a) --- updated-dependencies: - dependency-name: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml dependency-version: acdb9821a67fe0a275b39f1b388be364df7fbd4a dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/security-scan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index bf745dc..6ee7a64 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -40,6 +40,6 @@ jobs: # # Pin includes canonical .affine language detection and preserves # JSON.parseExn coverage after the ReScript-to-AffineScript migration. - uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@5e7575340961a21098d8d9600461038897016a4d # main 2026-08-24 + uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@acdb9821a67fe0a275b39f1b388be364df7fbd4a # main 2026-08-24 secrets: VERISIMDB_PAT: ${{ secrets.VERISIMDB_PAT }} From d4b508ef6a7d27a950e8c77f4f25c1e97bb3185e Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 15:41:17 +0100 Subject: [PATCH 2/3] chore(ci): regenerate actions.lock for the actions-group bump Regenerated with `gh actions-lock --no-narrow` (SHA pins kept); the workflow files are unchanged. `gh actions-lock --no-fix` now exits 0. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WPSJ7fBhVAMcpSffCBWUDo Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- .github/workflows/actions.lock | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index d5f8194..6c34f82 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -15,7 +15,7 @@ workflows: - 'google/clusterfuzzlite@v1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63' + - 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' '.github/workflows/coq-build.yml': - 'actions/checkout@v7.0.1' '.github/workflows/doc-consonance.yml': @@ -54,7 +54,7 @@ workflows: - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@stable' - 'rustsec/audit-check@v2.0.0' - - 'taiki-e/install-action@v2.87.15' + - 'taiki-e/install-action@v2.87.21' '.github/workflows/scorecard.yml': - 'hyperpolymath/standards@8750b94ac1bbe8c51ad13fe106669b13478f0b62' '.github/workflows/secret-scanner.yml': @@ -64,11 +64,6 @@ workflows: '.github/workflows/spark-theatre-gate.yml': - 'hyperpolymath/standards@fcb8669169b4e9f5d9848608df880ae5fae812b4' dependencies: - 'Swatinem/rust-cache@v2.8.2': - ref: 'v2.8.2' - commit: 'sha1-779680da715d629ac1d338a641029a2f4372abb5' - owner_id: 580492 - repo_id: 298565987 'actions/attest-build-provenance@v4.2.2': ref: 'v4.2.2' commit: 'sha1-4d101475d8b20a2381f78447822ac1eab6504dd8' @@ -143,9 +138,9 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2': + ref: 'v4.38.2' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1': @@ -161,7 +156,7 @@ dependencies: uses: - 'actions/checkout@v4.3.1' - 'dtolnay/rust-toolchain@v1' - - 'Swatinem/rust-cache@v2.8.2' + - 'swatinem/rust-cache@v2.8.2' 'hyperpolymath/standards@84355587cb2a1f86e6882de83514a32db2646e7a': ref: '84355587cb2a1f86e6882de83514a32db2646e7a' commit: 'sha1-84355587cb2a1f86e6882de83514a32db2646e7a' @@ -203,9 +198,14 @@ dependencies: commit: 'sha1-69366f33c96575abad1ee0dba8212993eecbe998' owner_id: 25397242 repo_id: 523199201 - 'taiki-e/install-action@v2.87.15': - ref: 'v2.87.15' - commit: 'sha1-4076c08d76dba979c11a7285295b0716c1d67908' + 'swatinem/rust-cache@v2.8.2': + ref: 'v2.8.2' + commit: 'sha1-779680da715d629ac1d338a641029a2f4372abb5' + owner_id: 580492 + repo_id: 298565987 + 'taiki-e/install-action@v2.87.21': + ref: 'v2.87.21' + commit: 'sha1-4cef1412cce204788f482e778a0b9187f9626a29' owner_id: 43724913 repo_id: 442947557 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555': From d0c8d842252e103da626c5651b5d61157ca2210a Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 15:46:05 +0100 Subject: [PATCH 3/3] chore(ci): re-pin dtolnay/rust-toolchain@stable to the live branch head Every Rust job died at setup with "Lockfile pin 6bed076 for dtolnay/rust-toolchain does not match ref `stable`": the workflows use the moving `stable` branch and it has moved. Re-pinned with `gh actions-lock --accept-moved` to 89b1218, which is `git ls-remote ... refs/heads/stable` today. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01WPSJ7fBhVAMcpSffCBWUDo Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- .github/workflows/actions.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 6c34f82..a857fcc 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -125,7 +125,7 @@ dependencies: repo_id: 260749683 'dtolnay/rust-toolchain@stable': ref: 'stable' - commit: 'sha1-6bed0761d98439e5a578e2877258200ad565ba87' + commit: 'sha1-89b12181fb390509a0842a86cc55eeb8eb928c1d' owner_id: 1940490 repo_id: 260749683 'dtolnay/rust-toolchain@v1':